Advertisement
Advertisement
Advertisement
18 September 2026ยท8 min readยทBy Markus Heill

AI-Enabled Bioweapons: A Wake-Up Call for Biotech

AI-enabled bioweapons are a wake-up call for biotech, as Anthropic and OpenAI leaders warn of risk while researchers urge caution.

AI-Enabled Bioweapons: A Wake-Up Call for Biotech

AI-enabled bioweapons have moved from science fiction to a live concern inside the very labs building artificial intelligence, and the people who know the technology best are the ones sounding the alarm.

The trigger was a public split inside the AI industry. The researcher Jacob Coxon announced he was leaving a role at Anthropic, charging that neither it nor OpenAI, where he had also worked, was acting responsibly. "The people building AI earnestly believe that it could kill us all by the end of the decade," he posted on X. Another Anthropic employee, Evan Hubinger, agreed in public. "We really do earnestly believe AI could kill all humans!" he responded. "I personally think it is >10% within the next decade."

That's not a hedge from an outsider. It's a probability estimate from someone paid to build the systems in question. And one of the specific ways these researchers fear AI could end us all is by helping design, create, and release a bioweapon.

What an AI-Enabled Bioweapon Actually Looks Like

Forget the Hollywood version. A bioweapon could be a highly lethal virus engineered to target people according to their genes. It could be a fungus that wipes out a crop and triggers food insecurity across a region. Or it could be a tasteless, odorless toxin slipped into a water supply, undetected until people start dying.

The concern isn't that AI will build these agents on its own. It can't. The real worry is simpler and much harder to dismiss, because AI tools can now help generate this kind of work, and that lowers an expertise barrier which once kept it confined to state programs and well-funded labs.

The Experiment That Changed the Conversation

These warning signs aren't hypothetical. In 2022, researchers at Collaborations Pharmaceuticals ran an experiment that should have stopped traffic, and they ran it with a tool they'd built to find potential drugs for human disease, an AI "molecule generator." Then they pointed it at the opposite problem. It's that simple.

a fork and knife

It took less than six hours. The model generated 40,000 molecules with the potential to serve as chemical warfare agents, and some of them, according to the design, were built to be more toxic than known nerve agents, which is a fact that doesn't get less alarming the more you sit with it. But that's what happened. They're more toxic than known nerve agents.

"Without being overly alarmist, this should serve as a wake-up call for our colleagues in the 'AI in drug discovery' community," the authors wrote at the time.

That wake-up call landed hard for David Magnus, a professor of medicine and biomedical ethics at Stanford University, who had been assessing the risks of misused medical science and biotechnology since the late 1990s. "That was very scary to me," he says. "Of course, everything since then has just sort of blown up."

The Knowledge Barrier Is Gone

Here is the part that has changed most since that 2022 experiment. Today, AI bots can answer questions spanning all realms of science. Anyone with a browser can query large language models trained on the knowledge and experience of, in the words of Dunja Sabra, a biosecurity researcher at the University of Hamburg in Germany, "almost every scientist who ever lived on this planet."

Those models can provide instructions and video training on how to conduct experiments. And they're not alone in this shift. Combine that with advances in biotech that have made gene editing and synthetic biology tools far more accessible, and the picture sharpens in ways that touch everything from classrooms to kitchen counters. The "DIY biology" movement has already enabled many people to set up labs at home. We've seen it. It's real.

"The chances are that someone determined would succeed eventually," Sabra says.

The Safeguards, and Why They Leak

There are protections in place, and they are worth understanding before panicking.

  • People who want to build new genomes must typically order DNA pieces from companies that screen for suspicious requests.
  • Responsible researchers run potentially risky work through "red-teaming," where independent scientists hunt for ways the research might be misused.
  • They also use "blue-teaming," where others develop potential mitigations.
  • AI companies have tweaked their tools to try to prevent them from offering scientific information that could be misused.

None of these protections are ironclad. In a report published last week, Anthropic acknowledged that people had attempted to use its models to explore ways to make the chikungunya virus more transmissible, create a form of bird flu more dangerous to humans, and build an "atlas of venom toxin peptides," among other things.

"We've got a constant back and forth," says Magnus. "We have to build better surveillance and screening tools, [but] AI is really good at figuring out ways around them."

His conclusion is uncomfortable: we will probably need to use AI to find ways to restrict the use of AI.

Not Every Biologist Is Losing Sleep

Not all scientists agree on the level of risk, and the disagreement is substantive rather than polite.

At a recent media briefing, some biologists at Imperial College London argued that AI tools simply are not good enough to fully develop bioweapons, and that testing new pathogens requires difficult, time-consuming, human work. Some think the guardrails already in place are sufficient.

Wendy Barclay, a professor of infectious disease at Imperial, pointed out that, as things stand, the greatest risk of a pandemic is not from a bioweapon at all. It is from pathogens already circulating. Take H5N1, the bird flu virus that has killed millions of birds and spread widely through US dairy cattle. Last month it was also detected in captive mink at a farm in Utah.

The Five-to-Ten-Year View

Sabra takes the longer view. She likes to think five to 10 years ahead. Countries should be strengthening their health-care systems, preparing antidotes to known toxins, and stockpiling medicines, she says. "We need to be prepared."

Then there is the detail that should make even skeptics pause. Kevin Esvelt, an MIT biologist who invented both technology to fast-track the propagation of a genetic feature through an entire population and ways to limit that technology, posted on X on Wednesday that a large language model had "disclosed a novel form of bioweapon that I hadn't realized was possible."

He added: "Please, for the love of God, children, the future of humanity, or whatever you consider holy, let's err on the side of caution here."

Why the Biotech World Should Be Paying Attention

The AI executives now say out loud what their own employees have been saying for longer. It's not new. Last weekend, Anthropic CEO Dario Amodei argued that AI carries serious risk and that progress should be slowed, a position that tracks with what people inside these companies have reportedly been voicing for quite some time now. OpenAI CEO Sam Altman responded on X. He said, "I agree with Dario that we need to pace the frontier.

That exchange matters for biotech. The same tools that accelerate drug discovery accelerate everything else built on the same underlying science, and that's the part people don't like to sit with. A molecule generator trained to find therapies doesn't know the difference between a cure and a weapon. It can't. It optimizes for the objective it's given.

The biotech industry sits at the intersection of every risk factor in this story: accessible gene editing, cheap synthetic biology, distributed lab work, and now AI systems that can tutor a determined amateur through the hard parts. The safeguards exist. They are also being tested, continuously, by people the companies themselves have flagged in their own reporting.

There is no tidy resolution here. Only a question the field has to answer: whether the tools get safer faster than the people misusing them get better.

Frequently Asked Questions

What happened when researchers at Collaborations Pharmaceuticals ran their 2022 experiment with an AI molecule generator?

They pointed a tool built to find potential drugs for human disease at the opposite problem. It took less than six hours for the model to generate 40,000 molecules with the potential to serve as chemical warfare agents, some of which were built to be more toxic than known nerve agents.

Why do researchers like Jacob Coxon and Evan Hubinger believe AI could end humanity, and what specific role do AI-enabled bioweapons play in that fear?

Both publicly stated they earnestly believe AI could kill all humans, with Hubinger estimating a probability greater than 10% within the next decade. One of the specific ways they fear AI could end us all is by helping design, create, and release a bioweapon.

How has the knowledge barrier that once confined bioweapon development to state programs and well-funded labs changed, according to the article?

AI bots can now answer questions spanning all realms of science, trained on the knowledge of, in Dunja Sabra's words, "almost every scientist who ever lived on this planet," and can provide instructions and video training on how to conduct experiments. Combined with more accessible gene editing and synthetic biology tools and the "DIY biology" movement, the article says the chances are that someone determined would succeed eventually.

What safeguards currently exist against the misuse of AI for bioweapons, and why do they leak?

DNA pieces must typically be ordered from companies that screen for suspicious requests, responsible researchers use red-teaming and blue-teaming, and AI companies have tweaked their tools to prevent misuse. However, Anthropic acknowledged people had attempted to use its models to explore making the chikungunya virus more transmissible, creating a more dangerous bird flu, and building an "atlas of venom toxin peptides," and Magnus said AI is really good at figuring out ways around the safeguards.

What practical preparations does Dunja Sabra recommend for the five-to-ten-year view, and what did Kevin Esvelt post that should make even skeptics pause?

Sabra says countries should strengthen their health-care systems, prepare antidotes to known toxins, and stockpile medicines, concluding that "we need to be prepared." Esvelt posted on X that a large language model had "disclosed a novel form of bioweapon that I hadn't realized was possible," and urged people to err on the side of caution.

Markus Heill
Written by
Gadgets and Software Writer

Markus Heill writes about technology and the tools we use every day, from smartphones to the services that run in the background. He is interested in how good design makes technology easier to live with.

๐Ÿ’ฌ Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement